nicholasjackson / cnitch
Container Snitch checks running processes under the Docker Engine and alerts if any are found to be running as root
☆78Updated 7 years ago
Alternatives and similar repositories for cnitch:
Users that are interested in cnitch are comparing it to the libraries listed below
- Falco container runtime security extras (default rulesets and more)☆49Updated 6 years ago
- The Container Security Book—a free book for practitioners☆82Updated 5 years ago
- Bash wrapper script for Aquasec Microscanner☆61Updated 5 years ago
- ☆55Updated 7 years ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆23Updated 2 weeks ago
- A @HashiCorp Vault plugin for authenticating and receiving policies via Slack.☆50Updated 5 years ago
- Kubernetes security scanner based on the open-source container vulnerability scanner Trivy.☆23Updated 4 years ago
- Web Application Firewall (WAF) on Kubernetes☆68Updated 3 years ago
- ☆33Updated 5 years ago
- A magic shim for Docker credential helpers 🪄☆69Updated 3 years ago
- Variety of kubectl krew tools usually security focused☆32Updated last year
- ⛔️ DEPRECATED Kubernetes operator and CLI tool for encrypting and managing Kubernetes secrets☆65Updated 8 months ago
- An actuary is a business professional who analyzes the financial consequences of risk.☆78Updated 7 years ago
- a tool to audit the istio service mesh☆173Updated 3 years ago
- ☆29Updated 2 months ago
- Docker authentication plugin to enforce a image pull policy. Whitelist Docker images allowed to be pulled.☆42Updated 7 years ago
- Kubernetes operator for Falco that allows developers to manage rules for detecting intruders and backdoors☆68Updated 4 years ago
- Container Security Workshop covering using Falco on Kubernetes.☆105Updated 3 years ago
- A proxy for docker.sock that enforces access control and isolated privileges☆143Updated 3 years ago
- Kubernetes Common Configuration Scoring System☆124Updated 2 years ago
- Kubernetes Pod RBAC Breakout☆37Updated last year
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆103Updated 5 years ago
- A Dockerfile that creates an image with known vulnerabilities.☆49Updated 3 years ago
- Generate K8s RBAC policies based on e2e test runs☆28Updated 3 years ago
- Server to be used as a Kubernetes mutating webhook to automatically inject a Vault agent sidecar or init container☆16Updated last year
- INTERCEPT / Policy as Code Auditing & Compliance☆84Updated 3 months ago
- A Kubernetes implementation in bash (srsly)☆17Updated 7 years ago
- Security risk analysis for Kubernetes resources☆74Updated 3 months ago
- Because Clair needs a friend☆31Updated 5 years ago
- A static analysis tool for Terraform plans.☆45Updated 2 years ago